Elder Fraud Response & Digital Evidence Preservation by Stefa GrovesElder Fraud Response & Digital Evidence Preservation by Stefa Groves

Elder Fraud Response & Digital Evidence Preservation

Stefa Groves

Stefa Groves

Remote Scam Response & Digital Evidence Preservation for a Gift Card Fraud Victim

A 75-year-old family member was targeted by a tech support scam operation across two separate incidents. The initial attack in March 2026 resulted in a $2,000 gift card loss and the covert installation of ScreenConnect Client, a remote access tool that gave the attackers persistent access to his device for over four months. A follow-up Microsoft impersonation scareware popup in July 2026 demanded $3,000. The victim refused and terminated the browser.
I was contacted after the second attempt and conducted a live, remote incident response session over the phone.

Incident 1 — March 17, 2026

Victim lost approximately $2,000 in a gift card scam.
ScreenConnect Client remote-access software was installed the same day.
Victim believed scammers never accessed the computer; discovery of the ScreenConnect installation indicated otherwise.
Gift card receipts and photos stored in the garage were inaccessible during the response session. Securing the computer and accounts took priority.

Incident 2 — July 28, 2026

Victim encountered a full-screen browser popup stating the computer was infected.
Displayed phone number: 888-951-7136
Displayed IP address: 172.217.14.206 (confirmed Google-owned infrastructure, not attacker-sourced)
Victim did not call the number or make any payment.
Used Ctrl + Shift + Esc to terminate the browser and restarted the computer multiple times.
Device: Dell Inspiron 15, Windows 11, approximately 14–15 months old

Remote Response Session — July 29, 2026

Conducted a nearly three-hour remote incident response session to assess the compromise, preserve evidence, and secure the victim's accounts. All work was performed by phone from approximately 2,500 miles away with a non-technical, emotionally distressed victim.
Actions completed:
Directed the victim to disconnect the computer from the internet
Ran a manual Seraph Secure scan
Located ScreenConnect Client installed on March 17, 2026
Attempted removal; uninstall failed with Windows Installer Error 1612 (original installation source unavailable)
Downloaded and installed Malwarebytes Free
Completed a full system scan: 174 items detected and quarantined
Changed the Microsoft/Outlook account password
Added a trusted recovery email
Reviewed Microsoft account sign-in history; no suspicious foreign logins identified
Confirmed the victim had already locked bank accounts, opened a new checking account, and had no active payment cards
Identified the displayed IP address as Google-owned, not attacker infrastructure
Began preparation of an IC3 federal report

Key Findings

The March 17 gift card scam and the ScreenConnect installation occurred on the same day.
A second scareware popup incident occurred months later using a similar tech support scam pattern.
The victim's computer was used for online banking during the entire period the remote-access software remained installed.
Evidence collection and federal reporting remain in progress.

Remaining Work

Obtain gift card receipts and photographs
Identify gift card brands, retailers, and transmission method
File IC3 complaint
File FTC fraud report
Report the displayed phone number to Microsoft
Complete full device remediation (delete quarantined items, remove residual ScreenConnect files)
Change remaining financial account passwords
Review additional online accounts accessed during the ScreenConnect installation period

Free Resource: "Before You Click" Scam Identification Checklist

I created this checklist for people to keep near their computers. If something feels off, run through it before you click, call, or pay anything.
Before You Click — Scam Identification Checklist
Before You Click — Scam Identification Checklist
Save it. Print it. Send it to someone who needs it.
This case study is a living document. Investigation and remediation are ongoing, and this project will be updated as new developments occur.
All identifying details have been anonymized.
Like this project

Posted Jul 30, 2026